Device and method for issuing a limited-use electronic certificate
Abstract
A process of issuing a limited-use electronic certificate. In operation, a public key infrastructure (PKI) device receives a request for an electronic certificate from an end entity. The PKI device detects an anomaly with respect to the request received from the end entity. The PKI device generates, based on the detected anomaly, a limited-use electronic certificate. The PKI then issues the limited-use electronic certificate to the end entity. When the end entity determines that the issued certificate is a limited-use certificate with limited-use attributes such as a shortened validity period or lowered assurance level, the end entity provides a visual and/or audio prompt indicating the issuance of the limited-use certificate and further including one or more corrective actions to be performed to eliminate the anomaly prior to sending a new request for an electronic certificate to the PKI device.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method of issuing a limited-use electronic certificate, the method comprising:
receiving, at a public key infrastructure (PKI) device, a request for an electronic certificate from an end entity;
detecting, at the PKI device, an anomaly with respect to the request received from the end entity;
generating, at the PKI device, based on the detected anomaly, a limited-use electronic certificate; and
issuing, at the PKI device, the limited-use electronic certificate to the end entity,
wherein the limited-use electronic certificate includes an attribute indicating that the certificate is signed by a certificate authority that is different from one of: a certificate authority requested by the end entity through the request; or a certificate authority that the PKI device would have used for signing the certificate in case of determining that no anomaly exists with respect to the certificate request.
2. The method of claim 1 , wherein the limited-use electronic certificate includes another attribute indicating a shortened validity period associated with the limited-use certificate.
3. The method of claim 2 , wherein the validity period is shorter than one of: a validity period requested by the end entity through the request; or a validity period that the PKI device would have included in the certificate in case of determining that no anomaly exists with respect to the certificate request.
4. The method of claim 1 , wherein the limited-use electronic certificate includes another attribute indicating a lower assurance level associated with the limited-use electronic certificate.
5. The method of claim 4 , wherein the assurance level is lower than one of: an assurance level requested by the end entity through the request, or an assurance level that the PKI device would have included in an issued electronic certificate in case of determining that no anomaly exists with respect to the request.
6. The method of claim 1 , wherein the request is one of a request for a new certificate, a request for a rekeyed certificate, or a request for a renewed certificate.
7. The method of claim 1 , wherein detecting the anomaly comprises:
determining that the request is received from the end entity while the end entity was located outside of a particular location.
8. The method of claim 1 , further comprising:
revoking one or more electronic certificates previously issued to the end entity when the anomaly is detected with respect to the request received from the end entity; and
transmitting a notification to the end entity, the notification indicating the revocation of one or more electronic certificates previously issued to the end entity.
9. The method of claim 1 , wherein detecting the anomaly comprises:
determining that the request is received outside of a particular time window.
10. The method of claim 1 , wherein detecting the anomaly comprises:
determining that a threshold number of requests for certificates are received from the end entity during a given time window.
11. The method of claim 1 , wherein detecting the anomaly comprises:
determining that the end entity has already been issued a threshold number of certificates.
12. A public key infrastructure (PKI) device, comprising:
a communications interface; and
an electronic processor communicatively coupled to the communications interface, the electronic processor configured to:
receive, via the communications interface, a request for an electronic certificate from an end entity;
detect an anomaly with respect to the request received from the end entity;
generate based on the detected anomaly, a limited-use electronic certificate; and
issue, via the communications interface, the limited-use electronic certificate to the end entity,
wherein the limited-use electronic certificate includes an attribute indicating that the certificate is signed by a certificate authority that is different from one of: a certificate authority requested by the end entity through the request; or a certificate authority that the PKI device would have used for signing the certificate in case of determining that no anomaly exists with respect to the certificate request.
13. The PKI device of claim 12 , wherein the limited-use electronic certificate includes another attribute indicating a shortened validity period associated with the limited-use certificate.
14. The PKI device of claim 12 , wherein the limited-use electronic certificate includes another attribute indicating a lower assurance level associated with the limited-use electronic certificate.
15. The PKI device of claim 12 , wherein the electronic processor is configured to detect an anomaly with respect to the request received from the end entity when the request is received outside of a particular time window, when a threshold number of requests for certificates are received from the end entity during a given time window, when the end entity has already been issued a threshold number of certificates, or when the request is received from the end entity while the end entity was located outside of a particular location.
16. The PKI device of claim 12 , wherein the electronic processor is configured to:
revoke one or more electronic certificates previously issued to the end entity when the anomaly is detected with respect to the request received from the end entity; and
transmit, via the communications interface, a notification to the end entity, the notification indicating the revocation of one or more electronic certificates previously issued to the end entity.
17. A method comprising:
generating, at an end entity, a request for an electronic certificate;
transmitting, at the end entity, the request for the electronic certificate to a public key infrastructure (PKI) device;
receiving, at the end entity, a response including an electronic certificate issued by the PKI device;
determining, at the end entity, based on one or more attributes included in the electronic certificate, that a limited-use certificate has been issued in response to an anomaly detected by the PKI device with respect to the request, wherein the one or more attributes indicate that the electronic certificate is signed by a certificate authority that is different from one of: a certificate authority requested by the end entity through the request; or a certificate authority that the PKI device would have used for signing the certificate in case of determining that no anomaly exists with respect to the certificate request; and
providing, at the end entity, a visual and/or audio prompt indicating the issuance of the limited-use certificate by the PKI device, the visual and/or audio prompt further including one or more corrective actions to be performed to eliminate the anomaly prior to sending a new request for an electronic certificate to the PKI device.
18. The method of claim 17 , wherein the limited-use certificate includes one or more of:
a first attribute indicating a shortened validity period associated with the limited-use certificate; and
a second attribute indicating a lower assurance level associated with the limited-use certificate.
19. The method of claim 17 , further comprising:
transmitting a request to access a service provided by an application server, the request including the limited-use certificate; and
receiving a limited access to the service provided by the application server.
20. The method of claim 17 , wherein the response further indicates revocation of electronic certificates previously issued to the end entity.
21. The method of claim 17 , wherein corrective actions include one or more of:
sending the new request during a time window allocated for the end entity to request certificates;
sending the new request after the expiry of a current time window;
sending the new request after the expiry of a predefined number of certificates currently issued to the end entity;
sending the new request for a certificate from a location predefined for the end entity to request certificates; and
sending the new request by including additional user credentials in the request for the electronic certificate.Join the waitlist — get patent alerts
Track US12041184B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.